The GnuTLS Library provides support for cryptographic algorithms andprotocols such as TLS. GnuTLS includes libtasn1, a library developed forASN.1 structures management that includes DER encoding and decoding.

Flaws were found in the way GnuTLS handles malicious client connections. Amalicious remote client could send a specially crafted request to a serviceusing GnuTLS that could cause the service to crash. (CVE-2008-1948,CVE-2008-1949, CVE-2008-1950)

We believe it is possible to leverage the flaw CVE-2008-1948 to executearbitrary code but have been unable to prove this at the time of releasingthis advisory. Red Hat Enterprise Linux 5 includes applications, such asCUPS, that would be directly vulnerable to any such an exploit, however.Consequently, we have assigned it critical severity.

Users of GnuTLS are advised to upgrade to these updated packages, whichcontain a backported patch that corrects these issues.

4. Solution:

Before applying this update, make sure that all previously-releasederrata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available athttp://kbase.redhat.com/faq/FAQ_58_10188